TA459
Overview
TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others.
Naming & attribution
TA459 is tracked under 1 names across the industry. It uses 5 documented ATT&CK techniques — more than 13% of the 174 groups tracked here.
| Name | First reported by |
|---|---|
| TA459 | Axel F |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- APT12 China — 3 shared techniques (43% overlap)
- Gallmaker — 3 shared techniques (38% overlap)
- DarkHydrus — 3 shared techniques (33% overlap)
- Nomadic Octopus Russia — 3 shared techniques (33% overlap)
- The White Company — 3 shared techniques (33% overlap)
- Transparent Tribe Pakistan — 4 shared techniques (27% overlap)
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1203
- Custom malware/implant development — ATT&CK: 4 attributed custom malware families
TTPs — 5 techniques across 2 tactics
Initial Access
-
T1566.001Spearphishing Attachment
Execution
-
T1059.001PowerShell -
T1059.005Visual Basic -
T1203Exploitation for Client Execution -
T1204.002Malicious File
Tools & malware (4)
gh0st RAT · NetTraveler · PlugX · ZeroT